/top/
/new/
/best/
/ask/
/show/
/job/
^
slacker news
login
about
←back to thread
NPM debug and chalk packages compromised
(www.aikido.dev)
1369 points
universesquid
| 2 comments |
08 Sep 25 15:37 UTC
|
HN request time: 0.558s
|
source
https://github.com/advisories/GHSA-8mgj-vmr8-frr6
1.
baloki
◴[
09 Sep 25 07:36 UTC
]
No.
45178717
[source]
▶
>>45169657 (OP)
#
A package on the list called ‘simple-swizzle’ turns out to be used in OpenNext which is an unexpected attack vector for sure.
replies(1):
>>45180289
#
ID:
GO
2.
yread
◴[
09 Sep 25 10:55 UTC
]
No.
45180289
[source]
▶
>>45178717 (TP)
#
> DO. NOT. USE. THIS. PACKAGE
> Used by 9.9m
https://github.com/qix-/node-simple-swizzle
↑